
我公司原用cisco2811路由器做VPN,模式是lan-to-lan,各分公司客户端使用路由器,无固定IP(ADSL拨号),使用一直正常。现需在2811上增加vpn client连接功能。但连接总有问题。6 L% p+ h8 |0 F
1、 原lan-to-lan配置
6 }8 b7 u1 p& E _+ T状态:lan-to-lan使用正常* D9 x6 |0 ^# K0 B+ h" H8 l
% f8 F" p, T: {3 p8 Z$ e ]
crypto isakmp policy 1 7 c# Q. h; O" J
encr 3des " S! b. j# i# a/ E7 L+ O
authentication pre-share 3 ]8 i2 H2 I( t4 z- f0 n1 m1 J) U
!
1 n; g" q6 x0 F# N) i* |crypto isakmp policy 3
- j5 n h. a9 B authentication pre-share 7 T8 r. _7 g' h' u& c/ Z% R X; n
crypto isakmp key 123456 address 0.0.0.0 0.0.0.0 " }; A) ^0 h7 C
!
! V+ K+ Z( t9 s; n* \' v8 Lcrypto ipsec transform-set VPN esp-des esp-md5-hmac
$ ]$ r0 a# M; {" m1 q4 I( f- g!
; @7 p$ Y C8 M8 ^* a1 {& y' dcrypto dynamic-map DYNMAP 1
+ {5 [' q* H1 n2 r8 n set transform-set VPN
% [# G4 s8 ]* Z# p4 f match address 102 / Z% q D9 F3 |! z V' u
! 3 x) G% q6 Z2 e9 O: G |( X
crypto map CMAP 60000 ipsec-isakmp dynamic DYNMAP ' d; H3 }) b b g5 j' W* q, ]* l
- P3 h: N( n: S' b/ }' Paccess-list 102 remark VPN_ACL IPSec Rule
5 D9 y- E* @$ X! l+ m; J7 maccess-list 102 permit ip 172.18.0.0 0.0.255.255 172.19.0.0 0.0.255.255" t) U2 K1 G1 R, A
2、 修改配置1
% w0 ], P% @5 w0 ^* k8 ]9 z- C$ q状态:cisco vpn client 连接正常,可以ping通内网,但原lan-to-lan不通。2 S% x, ?- q. g/ Q
% W. m% }7 V |/ e7 ]6 s
crypto isakmp policy 1
; I! d$ n" A# J+ ^1 J encr 3des
7 W% t: M) _% _) t authentication pre-share ; N" K- T3 i2 [, s1 Q! C) B
group 2 新增
9 N$ g4 B, o; A1 W B: `5 v; I* V! ' z, X5 ^6 m# l6 y/ C2 R0 ^' m7 m4 d
crypto isakmp policy 3 1 ?* y! |+ r4 S/ a0 F* Q$ d
authentication pre-share
/ O2 O6 ?' a# B+ T# q. z! @ G# Ucrypto isakmp key 123456 address 0.0.0.0 0.0.0.0
: ~) U/ X. z, Y" |7 s, n/ i! $ h+ b1 g( M8 Q1 G
Crypto isakmp client configuration group test 新增
$ C" \- a. b) j6 YKey test-1234; e1 n5 b" ~- w+ U2 v9 o4 F
Pool p1
1 I8 \3 s# }* Q3 fNetmask 255.255.255.0
9 L q, s) N8 M% J6 ^!
M8 v& O# ]' O3 x! X4 i% Kcrypto ipsec transform-set VPN esp-des esp-md5-hmac 5 ]' p6 Q- C- I0 i+ I' G$ Z2 l& }; G
crypto ipsec transform-set tran-hh esp-3des esp-md5-hmac 新增) M" D0 I) {) f0 ~% k5 |% J
!6 S# S6 d. Z' K+ Q8 c% g
crypto dynamic-map DYNMAP 1 $ {4 O7 X% L5 y+ f6 h
set transform-set VPN # I4 J1 ?- Z! B- R- f0 {
match address 102
8 t: `+ g! t$ \0 R1 [! : t# F+ n$ @* s9 O. n; M
Crypto dynamic-map dy-hh 1 新增- M3 S& V% y2 X
Set transform-set tran-hh
3 K+ _8 o" V M$ \7 a7 U) |+ {" J" s5 FReverse-route
) s3 ?4 \3 [& X7 Z!" y2 M7 g/ q& A3 d5 O& i: u3 A* n
Crypto map CMAP isakmp authorization list test 新增! U8 _4 O0 Z: }' c8 L
Crypto map CMAP client configuration address respond& u C" y# l$ |( b2 f, }# u
Crypto map CMAP 1 ipsec-isakmp dynamic dy-hh
1 Y3 ]' l# U: ecrypto map CMAP 60000 ipsec-isakmp dynamic DYNMAP ; {& {6 k7 ]4 o4 f8 w7 a
+ O0 r% E: V2 M$ _0 V) q
ip local pool p1 172.19.200.10 172.19.200.100
2 c1 w, {, B3 ?0 J1 p; Uaccess-list 102 remark VPN_ACL IPSec Rule
& V, X( _/ M8 f3 p1 F" r5 F; y% Iaccess-list 102 permit ip 172.18.0.0 0.0.255.255 172.19.0.0 0.0.255.2554 U; x$ Q8 `+ V @) A# a5 N2 S+ z# T
- \+ L" E, P1 V) T; g
5 ^8 ^. M& `, [5 A3、 修改配置2( U1 e3 Q. }0 S
状态:原lan-to-lan正常,Cisco vpn client 连接通过,在路由器上show cry ipsec sa,也正确,但client客户端不能ping通内网,也就是说虽连接了,但相互网络不通。
1 D' Y7 d0 F" X8 Qcrypto isakmp policy 3 0 [$ j, Y6 f/ f) t5 x" D* h
encr 3des
+ Z9 e" E" l% f, Q authentication pre-share
( D% n( ^# }/ u group 2 * g) t9 X' {- G
!7 t# F5 A( R6 p- o3 @
Crypto isakmp policy 10 4 G% ~1 D& W/ n; L) h
Encr 3des2 e9 @2 X/ [* H2 W# \9 p
Authentication pre-share
) n4 z7 M4 l. V* {% H!
% Q% C; S. q. h% u$ _. V9 |' Fcrypto isakmp key 123456 address 0.0.0.0 0.0.0.0
r' n* n& @! B' [, w5 _9 f!
9 L3 [* h! j3 z; x wCrypto isakmp client configuration group test
3 W9 l, o' e! `0 }3 |" I& y7 q5 EKey test-1234
7 f+ T4 y9 G9 ~$ f [8 W- {Pool p1, @( m$ b! Q1 A- x, O% O( _9 W
Netmask 255.255.255.0# q; }1 a. x7 }# `7 a
!- {4 i! Z4 N( R+ {/ A# ]
crypto ipsec transform-set VPN esp-des esp-md5-hmac ! u5 o- k/ `' V! L) i) o" ?! _& a& m
crypto ipsec transform-set tran-hh esp-3des esp-md5-hmac : s/ Y2 O% @" }
!3 z5 X; L# p( d/ {8 }$ ]( v
crypto dynamic-map DYNMAP 1 无法删除,不知如何删除,还在; l8 O( X% N+ O$ n- X; b& D
set transform-set VPN
5 P8 f' v) B( s0 X7 ~; S; v& R match address 102 8 S8 q7 A+ C/ o4 |
!
/ x% y5 c- g0 [1 @! W- _Crypto dynamic-map dy-hh 10
7 W1 n- A9 l" { Set transform-set tran-hh# }5 K" K5 @7 B) Q$ D0 _% T; A* n
Reverse-route
, N3 d: ^3 V& H3 p1 I0 b: y. hCrypto dynamic-map site 1# h: q7 ]4 D4 e# S
set transform-set VPN
9 `7 r1 y& J6 n3 r4 H& M- { match address 102 & J% _5 @. X% @3 ~, Y3 _6 e$ l
% Z0 O0 l3 l/ {4 O8 W!
4 u& i5 Z: y8 ^, [. T' uCrypto map CMAP isakmp authorization list test + }* S# K! D4 k3 [
Crypto map CMAP client configuration address respond, G* R3 I+ t# X0 j4 B
Crypto map CMAP 1 ipsec-isakmp dynamic site0 N, J" i0 a* A3 s9 |8 E& p
Crypto map CMAP 10 ipsec-isakmp dynamic dy-hh7 S3 D& f# ?: y* ^2 t1 q
crypto map CMAP 60000 ipsec-isakmp dynamic DYNMAP 无法删除,不知如何删除,还在0 h. e" \) o. ^6 q# { g! F, w# e
5 O% @: k& l% r+ y, Aip local pool p1 172.19.200.10 172.19.200.100- L8 T* X7 \5 C( L7 ?3 x5 N
4 f+ v- T. k5 M: g! I5 `% \6 h* j
access-list 102 remark VPN_ACL IPSec Rule & @ R& |$ [$ m3 o- c4 X/ q
access-list 102 permit ip 172.18.0.0 0.0.255.255 172.19.0.0 0.0.255.255 |
|